Adobe Reader zero-day vulnerability in active exploitation
ID: 2779268d-a3d9-57cd-a8c3-d8dd54bef9b6
STIX ID: report--2779268d-a3d9-57cd-a8c3-d8dd54bef9b6
Feed Name: Sophos Blogs
On April 7, 2026, researchers disclosed an actively exploited Adobe Reader zero-day (in use since December 2025) that allows attackers to abuse privileged Acrobat APIs via malicious PDFs with obfuscated JavaScript, enabling data theft and potential remote code execution; Russian-language lures suggest targeting of the oil and gas sector. The report supplies IoCs (MD5/SHA1/SHA256 hashes for malicious PDFs, C2 domain and IP:ports, and an Adobe Synchronizer User-Agent), lists recommended mitigations (monitor for Adobe patch, scan/block PDF attachments, user training), and references multiple external reports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
